User Profile
aollivierre305
Brass Contributor
Joined Aug 09, 2019
User Widgets
Recent Discussions
Re: Prevent enrollment of devices from external organizations in Intune
AtanasM Just block personal devices in Enrollment restrictions. BYOD is BYOD. It's unmanaged it does not matter where it's coming from because it's unmanaged and should blocked under enrollment restrictions.454Views1like0CommentsRe: How do I PowerShell Remote from an AAD machine to an AD machine?
I have WINRM completely stopped & disabled yet I'm able to run Enter-PSSession -ComputerName 192.168.128.140 -Credential 192.168.128.140\user just fine. - PS Remoting is much easier when both the client\server are both members of the same domain due to the trust that is already there because of the domain join o (not tested) have not tested if client\server are both joined to the same Azure AD o Other wise if they are both part of a workgroup on the same LAN then you will need to add the client to the server’s trusted hosts o (Not tested) or you can enable HTTPS transport and add the firewall rule for WSMAN/WINRM server - PS remoting will require enable-PSremoting in both cases whether the client\server are members of the same domain or member of a work group o you will run enable-PSremoting on the server (not the client) when client\server are both part of a workgroup (not AD domain) then you will use IP addresses instead of high level computer names to connect11KViews0likes0CommentsMissing dialpad/Keypad when on a 3 way call
Hello everyone, we are using Teams Business Voice for our company and all of us are missing the keypad only when on a 3 way call. One to One is fine and we see the key pad so we can navigate the IVR and key in certain extensions but the key pad is missing when inviting a 3rd party into the call. I'm wondering if this is a known issue or something that we should open a ticket with MS about ? Our users have been created and assigned the Teams Business Voice License for many month now. We are using the MS Teams Windows 10 Desktop version. We tried also dialing from the MS Teams web version but it drops the call immediately, so we can not even try there. We tried also dialing from the MS Teams mobile version, the dialpad option is there but does not do any thing when keying in a number.14KViews5likes16CommentsRe: How to use Intune manager uninstall Windows mail app
Sk-73 yeah I just noticed the same behavior where Stickynotes and Company Portal were also impacted by the policy which is a bizarre thing. I would try then with alternative methods like MDAC/WDAC or the Uninstall option or both as it seems the Applocker method would require more testing at this point.25KViews1like3CommentsRe: How to use Intune manager uninstall Windows mail app
I just learned this https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/wdac-and-applocker-overview#:~:text=Generally%2C%20it%20is,new%20feature%20improvements Try to use MDAC/WDAC instead of Applocker if you still want to try with Applocker then model the policy via GUI using the secpol.msc then export the policy to XML and open the XML with VS Code and take a look at the XML structure.25KViews1like5CommentsRe: How to use Intune manager uninstall Windows mail app
Applocker CSP here PRICESLY that (instead of uninstalling you DENY access) https://techcommunity.microsoft.com/t5/intune-customer-success/support-tip-using-applocker-to-create-custom-intune-policies-for/ba-p/364981 that article was from 2019 so here is the updated OMA-URI node and XML parts to use instead of the ones mentioned in the article but beside that follow everything in that article. You DO NOT need to start the App Identity service as it will automatically start (even though by default it is stopped and set to manual) OMA-URI (CASE SENSITIVE) ./Vendor/MSFT/AppLocker/ApplicationLaunchRestrictions/Grouping/StoreApps/Policy XML part to use a string value <RuleCollection Type="Appx" EnforcementMode="Enabled"> <FilePublisherRule Id="c3d7f207-377d-4512-bb18-d41c86063d54" Name="microsoft.windowscommunicationsapps, version 16005.14326.0.0 and above, from Microsoft Corporation" Description="" UserOrGroupSid="S-1-1-0" Action="Deny"> <Conditions> <FilePublisherCondition PublisherName="CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US" ProductName="microsoft.windowscommunicationsapps" BinaryName="*"> <BinaryVersionRange LowSection="16005.14326.0.0" HighSection="*" /> </FilePublisherCondition> </Conditions> </FilePublisherRule> </RuleCollection>26KViews1like9CommentsRe: Windows Hello for Business as laptop's MFA
Coexistence is really more of a sound passwordless strategy at least in early stages until you answer some of the hard questions when passwords are disabled https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/passwordless-strategy#:~:text=In%20this%20first%20step%2C%20passwords%20and%20Windows%20Hello%20for%20Business%20must%20coexist. Some high level questions to ask: - if %100 Passwordless was ready, why do not we see that at least as the DEFAULT experience with Win10/11 HOME ? Rolling out this tech to consumers to begin with seems more plausible - Why can't we have the MS auth app or FIDO2 security keys as the second factor (if PIN was the first factor) - What happens if the user forgets the PIN and passwords are disabled? How does some one go about remediation in a TIMELY manner ? one of the possible MEM reset options /ps script to enable the password cred again ? - What about RUN AS admin ? What do we there ?3.4KViews0likes1CommentRe: Problems enrolling devices into Intune
dmarquesgn - Ensure Modern Auth is enabled in the Org settings under admin.microsoft.com - Disable sec defaults - Disable the classic per user MFA and use CA policies to enforce MFA instead - Target all users all cloud apps all devices all locations with Grant and Require MFA via CA policy - Exclude Break the Glass accounts (max 2 Break the glass accounts are fine) from the CA policy - Exclude SMTP accounts from the CA policy or move SMTP traffic to a third party like SMTP2GO and then create a CA policy to block legacy auth all together in the tenant - Disable all forms of legacy auth/basic auth the Org settings under admin.microsoft.com - see again if Devices are now auto enrolling into Intune ~300 are quite high number and there has to be a good reason25KViews0likes5CommentsRe: Verify software is installed compliant
As mentioned already step 1 the app will need to show as an Azure AD registered app . Has nothing to do with Intune. CA policies apply for public and private apps in Azure AD only. Of course these apps will be registered there for purposes of SSO after all AAD is an identity provider and a Directory as a service. CA policies is simply an engine that processes signals from other systems and acts based on these signals. Now as far as I understand these are third party EDR/XDR tools so you may achieve better results with looking at Microsoft Defender for Endpoint/Business in combination with Sentinel and Microsoft security center. Intune plays nicely with MS Defender for Endpoint.3.6KViews1like0CommentsRe: How to use Intune manager uninstall Windows mail app
Sk-73 yeah users tend to click on the mail app instead of the Outlook. I would avoid removing native apps though not to break any basic functionality. I would instead prevent the users from using the app via CA policies or Applock. With some user Ed I always get them to use the browser for non work related mail accounts. Plus MS is retiring MS store for business.26KViews1like11Commentsattendees calling into conference bridge does not prompt or show in the meeting
Hello, We added M365 Business Premium Addon for Audio Conferencing and we also added the communication credits license. We also have purchased communication credits We recently purchased a toll free number through the Teams Admin center. When dialing into a teams meeting (whether we dial into the toll number or the toll free number). the participant joins the bridge but they are not in the meeting, they do not show up in the participants and the organizer does not see them to get prompted to allow the caller into the meeting. Vice versa if we dial out from the meeting to the caller number then it goes directly to the voice mail of the recipient. Happening in a specific tenant. Any ideas are appreciated!671Views0likes0Comments
Recent Blog Articles
No content to show